Your conversations deserve careful protection.
4C Pulse is developed with security as a layered responsibility: protecting connections, controlling access, safeguarding devices, and operating the service responsibly. The protections available to you can vary by app version.
How the system is structured
Android app → TLS-protected connection (HTTPS/WSS) → Apache web server → Node.js application service → MySQL database
Each layer has a different role. TLS helps protect information while it travels between the app and service. The application layer handles requests and access decisions. The database stores service data and should only be accessible through appropriately restricted server-side permissions.
Transport protection
Production web and messaging connections should use HTTPS and secure WebSocket connections (WSS) so data is encrypted in transit between the app and the service.
Account and application access
Authentication establishes an account or session, while authorization determines which actions and resources that session may access. These checks must be enforced by the server, not only by the app interface.
Server and database
Server-side controls should limit database privileges, protect configuration secrets, validate requests, and prevent unauthorized access to messages and media.
Device safeguards
Android platform protections, including Android Keystore where implemented, can help protect cryptographic keys on a device. They do not by themselves provide end-to-end encryption for messages.
Current protections and ongoing work
Security is continuous work rather than a single feature. We publish release information to help explain what is available and what is still being developed.
- Secure transport: HTTPS/WSS is the intended production transport for app-to-service communication.
- Access controls: authentication, authorization, server-side validation, and least-privilege database access are core requirements for the service.
- Operational safeguards: backup protection, monitoring, restricted administrative access, and audit logging should be maintained and reviewed as the service evolves.
- Advanced message security: end-to-end encryption (E2EE), device identity, and key-management capabilities must not be assumed to be available unless a specific production release explicitly confirms them.
HTTPS/WSS protects data in transit between endpoints. It does not, by itself, mean messages are end-to-end encrypted. This page does not claim independent security certification or that every listed control has been independently audited.
What you can do
- Install 4C Pulse only from the official download center.
- Keep your Android operating system and app updated to supported versions.
- Use a device screen lock and keep access to your device restricted.
- Review the Privacy Policy and Terms and Conditions.
- Check release announcements for updates to features and security-related work.
Report a security concern
If you believe you have found a security issue, please share a clear description of the issue and the steps needed to reproduce it. Avoid including other people's private messages, passwords, authentication codes, or unnecessary personal information.
Contact 4C Pulse about a security concern.
Security information is reviewed as the product changes. Feature availability may differ by release; consult the latest announcements for current product updates.
